Description
In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.
Remediation
References
Related Vulnerabilities
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4549)
WordPress Plugin Spam protection, AntiSpam, FireWall by CleanTalk Cross-Site Scripting (5.154)
Oracle JRE CVE-2019-2975 Vulnerability (CVE-2019-2975)
WordPress Plugin CF7 Invisible reCAPTCHA Cross-Site Scripting (1.3.1)
Sqlite NULL Pointer Dereference Vulnerability (CVE-2017-15286)